ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » WebSphere Message Broker (ACE) Support » Access to resources thru toolkit in v6

Post new topic  Reply to topic Goto page Previous  1, 2
 Access to resources thru toolkit in v6 « View previous topic :: View next topic » 
Author Message
ydsk
PostPosted: Tue Jan 24, 2006 2:56 pm    Post subject: Reply with quote

Chevalier

Joined: 23 May 2005
Posts: 410

An update on the issue:

If the domain id is ABC\xyz, the syntax to create an ACL (giving full access to the domain user-id )on a AIX-Configmgr ( CONFGMGR) is:

mqsicreateaclentry CONFGMGR -u ABC\\xyz -a -x F -p

But interestingly, the following command with the -m flag also does the same job exactly:

mqsicreateaclentry CONFGMGR -u xyz -m ABC -x F -p

The above can be verified by issuing an mqsilistaclentry OR by accessing the configmgr with the id from a toolkit.

Not sure why the -m flag ( which is actually meant for machine name alone as per documentation ) is unable to distinguish between a machine name and a domain name.

This is a security hole....any user can change his machine name to a valid domain-name and just create an id that has permissions on the configmgr, and access the configmgr.

Thanks.
ydsk.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Goto page Previous  1, 2 Page 2 of 2

MQSeries.net Forum Index » WebSphere Message Broker (ACE) Support » Access to resources thru toolkit in v6
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.